Privacy Policy

Version 1.0  ·  Last updated: 26 February 2026  ·  Domain: sales.easygate.pt

1. Identity of the Data Controller

The data controller for your personal data is the entity operating the website sales.easygate.pt. For any questions regarding the processing of your data, please contact us at info@sales.easygate.pt.

This Privacy Policy applies to all personal data collected and processed through sales.easygate.pt, including the digital products store, the contact/support form and all associated services.

2. Legal Framework

The processing of your personal data is carried out in accordance with:

3. Personal Data Collected and Purposes

3.1 Purchase of digital products

DataPurposeLegal basis (GDPR)
Full nameBuyer identification; personalisation of confirmation emailArt. 6(1)(b) — performance of contract
Email addressSending the product download link; order-related communicationsArt. 6(1)(b) — performance of contract
Company (optional)Tax identification; invoicingArt. 6(1)(b) and (c) — contract and legal obligation
Address, postcode, cityCompliance with VAT obligations; invoicingArt. 6(1)(c) — legal obligation (tax)
CountryDetermination of applicable VAT rate (Directive 2006/112/EC and OSS)Art. 6(1)(c) — legal obligation (tax)
VAT number (optional)VIES verification for B2B reverse charge; tax evidenceArt. 6(1)(c) — legal obligation (tax)
IP addressGeolocation evidence for customer country determination (Reg. EU 1042/2013); fraud preventionArt. 6(1)(f) — legitimate interest
Locale/languagePersonalisation of communications; audit trailArt. 6(1)(b) — performance of contract
PayPal transaction IDsPayment verification and records; refund managementArt. 6(1)(b) and (c) — contract and legal obligation

3.2 Contact and support form

DataPurposeLegal basis (GDPR)
Name, email addressIdentification and response to enquiryArt. 6(1)(a) — consent (voluntary submission)
Subject and messageProvision of customer support serviceArt. 6(1)(a) — consent
Attachment (support form)Diagnosis and resolution of reported issuesArt. 6(1)(a) — consent
IP addressSecurity and abuse preventionArt. 6(1)(f) — legitimate interest

3.3 VAT fiscal evidence

To comply with Regulation (EU) No. 1042/2013 (Art. 24a of Reg. 282/2011), which requires at least two non-contradictory pieces of evidence of the customer's country for digital services supplied to EU consumers, we retain:

Mandatory retention period: 10 years, pursuant to Art. 52 of Directive 2006/112/EC and Portuguese tax legislation.

4. Cookies

We use only strictly necessary and functional cookies. For detailed information on the cookies used, their purposes and duration, please see our Cookie Policy.

5. Sharing Data with Third Parties

5.1 PayPal

When you make a purchase, the data required for payment processing is transmitted to PayPal (Europe) S.à r.l. et Cie, S.C.A., headquartered in Luxembourg. PayPal acts as an independent data controller for payment data. See the PayPal Privacy Policy.

5.2 Email service provider (SMTP)

Confirmation and notification emails are sent via an SMTP provider, which acts as a data processor and only processes data for the purpose of email delivery.

5.3 European Commission VIES service

When you provide a VAT number, it is transmitted to the European Commission's VIES API for verification. The Commission is not a data processor under the GDPR; this is a consultation of a public European service. The result is retained for tax audit purposes.

We do not sell, rent or share your personal data with third parties for commercial or advertising purposes.

6. International Data Transfers

Your data is processed and stored on servers located within the European Economic Area (EEA). PayPal may transfer data to the United States of America under appropriate safeguards pursuant to Art. 46 GDPR (standard contractual clauses and/or adequacy decision).

7. Retention Periods

Data categoryPeriodBasis
Order and transaction data (including tax data)10 yearsTax obligation (VAT Code; Reg. EU 1042/2013)
VAT fiscal evidence10 yearsArt. 52 of Directive 2006/112/EC
Contact and support messages2 yearsLegitimate interest (complaints management)
Access logs (IP addresses)1 yearLegitimate interest (security)
Email dispatch logs1 yearLegitimate interest (diagnostics)

8. Your Rights

Under the GDPR, you have the following rights regarding your personal data:

Important note: The right to erasure does not apply to data we are legally required to retain (e.g. tax data for transactions during the mandatory 10-year retention period).

To exercise any of these rights, contact us at info@sales.easygate.pt with adequate identification. We will respond within 30 days.

9. Supervisory Authority

The competent supervisory authority in Portugal is the Comissão Nacional de Protecção de Dados (CNPD):

10. Data Security

We implement appropriate technical and organisational measures to protect your personal data, including HTTPS/TLS encryption, cryptographically secure unique download tokens, restricted admin access with password authentication, IP-based rate limiting against brute force attacks, and web-accessible file directory protection.

11. Updates to this Policy

We may update this Privacy Policy as necessary. The updated version will be available on this website with a revised “last updated” date. We recommend checking this page periodically.